Government Technology Insider
  • About
  • State & Local
  • Civilian
  • Defense & IC
SUBSCRIBE
No Result
View All Result
  • Acquisition
  • AI & Data
  • Cybersecurity
  • Digital Transformation
  • Hybrid Work
    • Work Smarter
  • Public Safety
  • Resources
    • The Frontlines of Customer Experience
    • Innovative Solutions for Connecting Agencies
    • Be Ready For What’s Next
Government Technology Insider
  • Acquisition
  • AI & Data
  • Cybersecurity
  • Digital Transformation
  • Hybrid Work
    • Work Smarter
  • Public Safety
  • Resources
    • The Frontlines of Customer Experience
    • Innovative Solutions for Connecting Agencies
    • Be Ready For What’s Next
No Result
View All Result
Government Technology Insider
No Result
View All Result
Home Digital Transformation

New NIST Policies on Cloud Coming This Year

by GTI Editors
June 3, 2015
in Digital Transformation
Reading Time: 2 mins read
A A
Share on FacebookShare on Twitter

The National Institute of Standards and Technology has two new standards being drafted that will further address cloud security, including a methodology that will help organizations determine what kind of cloud would best fit their needs.

Dr. Michaela Iorga, senior security technical lead for cloud computing at NIST, told the audience at the Cloud Security Alliance federal summit that concerns about the safety of data is the primary impediment to adoption.

“We have to understand what we fear the most” about the cloud, Iorga said. “It’s loss of control – 75 percent fear losing control of their data. We do not trust the cloud. [So] how can we build that trust?”

The new standards – 800-173, Cloud-Adapted Risk Management Framework: Guide for Applying the Risk Management Framework to Cloud-based Federal Information Systems, and 800-174, Security and Privacy Controls for Cloud-based Federal Information Systems – are designed to overlay and elaborate upon already-existing standards that lay out the basics for cloud architecture and security.

“In our cloud security reference architecture [NIST 500-299], we had an epiphany” for the draft cloud risk management standard, Iorga said. “This methodology can help select the best-fitting cloud architecture … Our parents used to buy fabric and make their own suits, and they fit perfectly. What you have to do is your homework. Don’t purchase the cloud first, then tailor it. This is what we learned from the initial NIST architecture reference document.”

Iorga suggested that organizations use FedRAMP, CSA’s Security, Trust and Assurance Registry (STAR), or other certification and authorization programs to make decisions about cloud. “You build a trust relationship with that entity,” she said, but “you have to verify. You can’t trust and not verify.”

Organizations looking to move to the cloud need to have real teams in place to help evaluate providers, Iorga said. “It’s not a one-person job … Acquisition experts in the past asked for a 10-page summary of what they should look for. That’s not going to happen.”

Privacy is one aspect of security policy. “If we do it right, 800-174 should have all the baseline controls from FedRAMP already in place,” Iorga said. The draft policy will extend beyond those baselines, however. “We tried to look at what would be necessary for different impact levels. We are planning to do the same thing with FedRAMP Plus.”

 

Tags: Cloud Security AllianceCloud-Adapted Risk Management FrameworkFedRAMPnational institute of standards and technologyNIST

RELATED POSTS

Four Smart Strategies to Combat the Log4j Security Vulnerability
Cybersecurity

Four Smart Strategies to Combat the Log4j Security Vulnerability

June 6, 2022
Alerts
Civilian

Identify, Protect, Detect, Respond, and Recover: How Alerts Empower Agencies in a Tough Cybersecurity Environment

February 17, 2022
FedRAMP solutions
Civilian

In 2022, Agencies Will Return Their Focus to FedRAMP Solutions

January 11, 2022
Please login to join discussion

TRENDING NOW

  • Advana

    Meet Advana: How the Department of Defense Solved its Data Interoperability Challenges

    5386 shares
    Share 2154 Tweet 1347
  • The Future for the Air Force Depends on Agility and Resilience at the Edge

    87 shares
    Share 35 Tweet 22
  • For the Army to Reach Modernization Goals, a Tactical Data Fabric is Crucial

    42 shares
    Share 17 Tweet 11
  • Design Secure Application Software That Transforms Government Agencies

    12 shares
    Share 5 Tweet 3

CONNECT WITH US

MaaS Nebula Software Factory Banner Ad MaaS Nebula Software Factory Banner Ad MaaS Nebula Software Factory Banner Ad
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Ad Advertisement Banner Ad Advertisement Banner Ad
Advertisement Banner Advertisement Banner Advertisement Banner
Advertisement Banner Advertisement Banner Advertisement Banner

BECOME AN INSIDER

Get Government Technology Insider news and updates in your inbox.

Strategic Communications Group is a digital media company that helps business-to-business marketers drive customer demand through content marketing, content syndication, and lead identification.

Related Communities

Financial Technology Today
Future Healthcare Today
Modern Marketing Today
Retail Technology Insider
Today’s Modern Educator

Quick Links

  • Home
  • About
  • Contact Us

Become a Sponsor

Strategic Communications Group offers analytics, content marketing, and lead identification services. Interested?
Contact us!

© 2021 Strategic Communications Group, Inc.
Privacy Policy      |      Terms of Service

No Result
View All Result
  • Home
  • About Government Technology Insider
  • State & Local
  • Civilian
  • Defense & IC
  • Categories
    • Acquisition
    • AI & Data
    • Digital Transformation
    • Cybersecurity
    • Hybrid Work
  • Contact Us